CVE-2024-57241

MEDIUM

Dedecms - Open Redirect

Title source: rule

Description

Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.

Exploits (2)

github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/DedeCms_CVE-2024-57241_RedirectUrl.py
nomisec WORKING POC 3 stars
by hkl1x · poc
https://github.com/hkl1x/CVE-2024-57241

Scores

CVSS v3 6.5
EPSS 0.0660
EPSS Percentile 91.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-601
Status published

Affected Products (1)

dedecms/dedecms

Timeline

Published Feb 11, 2025
Tracked Since Feb 18, 2026